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CLAIM S 

What is claimed is: 

1 . A method of filtering data in a computer network, the method comprising: 

receiving data in a first computer; 

5 scanning the data against at least a portion of a knowledge base in the first 

computer; 

forwarding the data to a second computer over a computer network; and 

scanning the data against at least a portion of a knowledge base in the second 
computer, the portion of the knowledge base in the second computer including 
10 information not present in the portion of the knowledge base in the first computer. 

2. The method of claim 1 wherein the knowledge base in the first computer is a 
subset of the knowledge base in the second computer. 

3. The method the claim 2 wherein the knowledge base in the second computer has 
segments 1,2,3,...p, the knowledge base in the first computer has segments 1,2,3,...m, 

15 p is greater than or equal to m, the data are scanned from 1 to m in the first computer, 
and the data are scanned from m+1 to p, if p is greater than m, in the second computer. 

4. The method of claim 1 further comprising: 

in the first computer, determining a designated destination computer of the data, 
and wherein the potion of the knowledge base in the first computer is selected based on 
20 a resource capacity of the destination computer. 
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5. The method of claim 5 wherein the knowledge base in the first computer and the 
knowledge base in the second computer comprise a virus pattern file. 

6. The method of claim 1 wherein the data are scanned in the first computer and in 
the second computer for computer viruses. 

5 7. The method of claim 1 wherein the data are scanned in the first computer and in 
the second computer for spam. 

8. The method of claim 1 wherein the data are scanned in the first computer and in 
the second computer for unauthorized intrusion into the computer network. 

9. The method of claim 1 wherein the data comprise a file. 

10 10. A system comprising: 

a content filtering system in a first computer, the content filtering system being 
configured to determine a destination computer of an incoming data and to scan the 
incoming data against a knowledge base in the first computer based on a resource 
capacity of the destination computer; and 

1 5 a content filtering agent in a second computer, the second computer being the 

destination computer of the of the incoming data, the content filtering agent being 
configured to scan the incoming data against a knowledge base in the second computer 
based on an amount of scanning performed by the content filtering system on the 
incoming data in the first computer. 

20 11. The system of claim 10 wherein the knowledge base in the first computer and the 
knowledge base in the second computer comprise a virus pattern file. 
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12. The system of claim 10 wherein the knowledge base in the first computer and the 
knowledge base in the second computer comprise anti-spam related information. 

13. The system of claim 10 wherein the knowledge base in the first computer and the 
knowledge base in the second computer comprise unauthorized intrusion related 

5 information. 

1 4. The system of claim 1 0 further comprising: 

a capacity mapping table in the first computer, the capacity mapping table being 
configured to indicate resource capacities of computers coupled to the first computer 
over a network. 

10 1 5. The system of claim 10 wherein the resource capacity comprises storage space. 

1 6. The system of claim 10 wherein the resource capacity comprises processor 
speed. 

1 7. The system of claim 10 wherein the first computer comprises an appliance 
performing antivirus functions. 

15 18. A method of detecting viruses in an incoming data, the method comprising: 

comparing a content of an incoming data against a first set of virus patterns in a 
pattern file in a first computer serving as a gateway security node; 

forwarding the incoming data to a second computer; and 

comparing the content of the incoming data against a second set of virus 
20 patterns in a pattern file in a second computer, the second set of virus patterns including 
virus patterns that are different from that in the first set of virus patterns. 



-18- 



Attorney Docket No. 10033.000300 

1 9. The method of claim 1 8 wherein virus patterns in the first set of virus patterns are 
selected based on a resource capacity of the second computer. 

20. The method of claim 18 wherein the pattern file in the first computer is a subset 
of the pattern file in the second computer. 
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